Microsoft Entra ID
Provisioning

Plan Cloud Sync Topologies

In brief

The documentation now states that cloud-synced groups can contain only on-premises synchronized users and additional cloud-created security groups, and that all users must have `onPremisesObjectIdentifier`. The example link and diagram descriptions were also updated.

What Entra admins need to know

Review group provisioning designs against the newly documented membership requirements.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Multi-forest, single Microsoft Entra tenant

Topology for a multi-forest and a single tenant

Multiple AD forests are a common topology, with one or multiple domains, and a single Microsoft Entra tenant.

Piloting Microsoft Entra Cloud Sync in an existing hybrid AD forest

Topology for a single forest and a single tenant

The piloting scenario involves the existence of both Microsoft Entra Connect and Microsoft Entra Cloud Sync in the same forest and scoping the users and groups accordingly. NOTE: An object should be in scope in only one of the tools.

(Public Preview)

Diagram for merging objects from disconnected sources

In this scenario, the attributes of a user are contributed to by two disconnected Active Directory forests.

:::image type="content" source="media/plan-cloud-provisioning-topologies/single-forest-group-writeback.png" alt-text="Conceptual diagram of single forest writeback." lightbox="media/plan-cloud-provisioning-topologies/single-forest-group-writeback.png":::

The simplest group provisioning topology is a single on-premises forest, with one or multiple domains, and a single Microsoft Entra tenant. For an example of this scenario,scenario see Provision users and groups from Microsoft Entra ID to Active Directory.Provision groups to Active Directory

Multi-forest group provisioning to Active Directory

This configuration is advanced and there are a few things to remember with this topology:

  • Group membershipGroups provisioned to AD includesusing cloud sync can only members that have an AD account. Those members can becontain on-premises synchronized users, cloud-managed users that Cloud Sync provisions to AD because they're in scope of user provisioning,and / or otheradditional cloud created security groups.
  • On-premises synchronizedAll of these users must have the onPremisesObjectIdentifier attribute set on their account.
  • The onPremisesObjectIdentifier must match a corresponding objectGUID in the target AD environment.
  • An on-premises users objectGUID attribute to a cloud users onPremisesObjectIdentifier attribute can be synchronized using either Microsoft Entra Cloud Sync (1.1.1370.0) or Microsoft Entra Connect Sync (2.2.8.0)
  • Inside your tenant you may share a common group that contains users from both forests.
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…